Malicious PDF — malware analysis report

Static analysis result for SHA-256 319be4033cc8b743…

MALICIOUS

PDF

74.6 KB Created: 2020-08-08 05:43:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7b13c81e659df74d97be2da9b488032a SHA-1: 52413587b751ffe56c5c955897e87cbc938ff613 SHA-256: 319be4033cc8b743fe75dcdde5a2938100724140b810d20ec37bcbd8e281c85c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/pify?keyword=biceps+exercise+chart+pdf'. This indicates the document's primary purpose is to redirect the user to a potentially harmful site. The document body, though heavily obfuscated, contains text fragments that align with the lure of an exercise chart, further supporting the social engineering aspect of the attack. The presence of numerous other embedded URLs, many pointing to Shopify, suggests a link farm or content distribution strategy, with the malicious redirector being the primary threat.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=biceps+exercise+chart+pdf
    • http://files.polarustravel.com/uploads/1/3/2/3/132302816/4169459.pdf
    • http://files.vtel.com/uploads/1/3/1/4/131407705/xevukivimewim_xebomon_jidimeforav_zedixekepi.pdf
    • http://files.litchfieldgardenclub.org/uploads/1/3/2/8/132815175/vezesoxabeno.pdf
    • http://files.lettymartinesdesign.com/uploads/1/3/1/3/131398292/vibijuwevugafeg_bikijeguzaxisox_rekositezipid_gawarokawido.pdf
    • https://cdn.shopify.com/s/files/1/0430/2536/7194/files/angielski_kurs_dla_wiecznie_pocztkujcych.pdf
    • https://cdn.shopify.com/s/files/1/0435/0767/9397/files/batching_plant_file.pdf
    • https://cdn.shopify.com/s/files/1/0434/5679/0681/files/definicin_de_autoestima_segun_autores.pdf
    • https://cdn.shopify.com/s/files/1/0429/9754/7157/files/john_deere_push_mower.pdf
    • https://cdn.shopify.com/s/files/1/0434/0521/3846/files/radajadafotugemibesozodu.pdf
    • https://cdn.shopify.com/s/files/1/0431/5702/9019/files/7800315712.pdf
    • https://cdn.shopify.com/s/files/1/0432/0047/9391/files/24540836622.pdf
    • https://cdn.shopify.com/s/files/1/0433/5009/8078/files/35501174911.pdf
    • https://cdn.shopify.com/s/files/1/0434/7016/0032/files/68552086959.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cde0.bin
1d1b4a59d10acbaaa3b835c62665dca819ccf2ed77e442333819554eb77ca1c7
pdf-font-stream PDF embedded font (sfnt) at offset 0xCDE0 5328 bytes
font_01_sfnt_off0000e001.bin
8de4b2f4fd615698c321475317b124a61bef034588e52ac495b196dabb16f56b
pdf-font-stream PDF embedded font (sfnt) at offset 0xE001 11836 bytes
font_02_sfnt_off0001084c.bin
97f6b80edf08cc5b0df0b0498a98c215780675af88f340742e7e855906399d0f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1084C 16104 bytes